Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
2026-07-19T08:51:42Z•3f4af3a9b9a12fd1c8cb312579c9ff2b902d788c0d783d1ecc5cfe1e2af23756
CISADaxinEYErnst & YoungFortiSandboxFortinetHollowByteKNXKnown Exploited VulnerabilitiesMicrosoft SharePointNichireiOpenSSLOracleScattered SpiderStarland RATStupigTuxBot v3','IoT botnet','AI-generated malware','DoS','RCEUAT-11795WLDRWordPressdata breachrootkitsupply-chainthird-partywp2shell
What happened
Multiple high-impact security events and disclosures: public exploits released for two critical WordPress “wp2shell” flaws (CVE-2026-63030, CVE-2026-60137) that can be chained for pre-auth remote code execution; Okta/Red Team disclosed an OpenSSL memory-exhaustion DoS named “HollowByte”; Symantec found the long-running China-linked Daxin kernel rootkit and a new Stupig backdoor on a manufacturer’s network; U.S. CISA added multiple flaws (including CVE-2023-4346) to its Known Exploited Vulnerabilities catalog (Fortinet FortiSandbox, Microsoft SharePoint, KNX, Oracle); Ernst & Young reported a 3
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 3f4af3a9b9a12fd1c8cb312579c9ff2b902d788c0d783d1ecc5cfe1e2af23756
- Enrichment time
- 2026-07-19T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.